PT-2026-67744 · Kotaemon · Kotaemon

·

CVE-2026-69098

·

Published

2026-08-04

·

Updated

2026-08-04

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions kotaemon versions prior to 0.12.1
Description An insecure deserialization issue exists in the 'check connection' endpoint. Unauthenticated attackers can instantiate arbitrary Python classes by providing crafted YAML or JSON input containing a type field. By overriding the type field with the subprocess.check output() function and providing arbitrary arguments, an attacker can achieve remote code execution with the privileges of the application process.
Recommendations Update kotaemon to a version later than 0.12.0. As a temporary mitigation, restrict access to the 'check connection' endpoint.

Exploit

Fix

RCE

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-69098

Affected Products

Kotaemon